Collaboration agents cross from answering to acting, and ship the permissions to match
The week in collaboration
The assistants stopped waiting to be asked. Across the sector's most active products this week, the AI layer crossed the same line at once — from answering a question a person typed to doing work on its own, on a schedule, in the background of a live conversation, or across a whole archive with permission to write. Tana turned its voice agent into a background worker that runs several requests at once while a meeting carries on. Double opened a private beta for accounting agents that run recurring work across a client book and escalate only when a human is needed. Readwise pointed Ghostreader at everything a user has ever saved and gave it tools that tag, note, and edit. Three independent products, three moves from responding to acting, in the same seven days.
What keeps this from reading as hype is the second pattern underneath it: every one of these releases ships a permission model in the same breath. Readwise gates each Ghostreader tool as always-allow, ask-first, or disabled. Double is pairing its agents with role-based restrictions on who can edit what. Memos rebuilt its MCP endpoint and now boots private by default. The vendors clearly understand that an assistant with write access is only sellable if the customer controls exactly what it may touch — so the access-control work is arriving as feature, not afterthought. The interesting collaboration story this week is not that the agents got smarter; it is that the industry started building the guardrails that let them act unattended.
Leaders
Tana is the clearest expression of the pattern. Its 28 August release lets the voice agent handle several requests concurrently during a meeting — looking things up, drafting documents, acting in connected tools — while reading the day's agenda, pinned items, and the shared screen for context. It is the hinge from passive capture to active participation, and it caps an arc that has been claiming the meeting surface release by release.
Double made the same jump in a narrower domain. Scheduled and event-triggered agents now run recurring accounting tasks across selected clients and escalate for review, where every prior Ask Double release only answered a question someone typed. The accounting engine deepening underneath — accruals, revenue-share allocations, loan amortization — is the supply of work those agents need something to do.
Readwise extended Ghostreader past the open document to the entire library, answering with citations that link back to the source and acting through permission-gated tools. Coming two weeks after a from-scratch rebuild of both mobile apps, it is the payoff side of a single bet: get more into the library by voice and camera, then give something the reach to use the volume.
GitHub is consolidating rather than expanding. Copilot agent sessions entered public preview in Slack — a shared, channel-visible session that breaks the one-developer-one-session shape — while the platform pruned Classroom and flagged policy and billing changes. The agent surface widens as governance hardens at the same cadence.
Document360 approached agents from the data side, replacing its public API with a v3 that adds OAuth 2.0 and role-scoped keys, then turned back to make the WYSIWYG editor multiplayer. Scoped credentials are the precondition an enterprise needs before it lets anything — human or agent — write to the knowledge base.
Wildcards
Skedda is off the agent pattern entirely and worth watching for it. Its new Occupancy tab turns presence data into attendance reporting — daily headcount, attendance by person or team, patterns by user tag. A booking tool that measured rooms now measures the people in them, which is where the return-to-office debate actually gets adjudicated.
Capacities moved on price, not product. Pro+ and Believer+ sell AI budget as optional add-ons layered over existing plans, with top-ups when a user runs out. It introduces a consumption dimension alongside the subscription tier — a quiet signal of what the agent features elsewhere in this sector will eventually cost to run.
Themes that compounded
- Agents crossed from answering questions to acting unattended — on a schedule, in the background, or across an entire archive — at Tana, Double, and Readwise in the same week.
- Per-tool permission models shipped alongside the write access, treating library and client-book mutation as something the user grants rather than the assistant assumes.
- The meeting itself became the context agents read from, not just a thing to transcribe, at Tana.
- API and MCP rebuilds made knowledge bases addressable by machines first — scoped keys at Document360, a stateless MCP endpoint at Memos.
- Making the tool callable from outside it recurred as its own thread, with external webhooks now able to start a workflow at Hive.
Watch this week
The betas are the tell. Double's AI Agents and Readwise's write-capable Ghostreader are both gated or private, and the honest open question each vendor names is the same one: what happens when an unattended agent edits a document or posts to a client book and gets it wrong. Expect the next moves to be less about new agent capability and more about the review, audit, and rollback surfaces that make the capability safe to leave running — the workflow, not the model. Watch too whether Capacities's metered-AI pricing spreads, because someone has to pay for all these agents to keep working while nobody is watching.